Mar 25, 2013

Congress Bulls Into China's Shop

Anger over Chinese cyberespionage continues to mount in Congress, and it's beginning to show in legislation. Not just the bills Congressmen introduce, the ones Congress passes.

Demonstrating remarkable bipartisan angst about Chinese hacking and the risks in Chinese high tech equipment, Congress has added tough sanctions to the continuing resolution that funds the federal government and is now awaiting the President's signature. The sanctions provision bars federal government purchases of IT equipment "produced, manufactured or assembled" by entities "owned, directed, or subsidized by the People's Republic of China" unless the head of the purchasing agency consults with the FBI and determines that the purchase is "in the national interest of the United States":

Sec. 516. (a) None of the funds appropriated or otherwise made available under this Act may be used by the Departments of Commerce and Justice, the National Aeronautics and Space Administration, or the National Science Foundation to acquire an information technology system unless the head of the entity involved, in consultation with the Federal Bureau of Investigation or other appropriate Federal entity, has made an assessment of any associated risk of cyber-espionage or sabotage associated with the acquisition of such system, including any risk associated with such system being produced, manufactured or assembled by one or more entities that are owned, directed or subsidized by the People's Republic of China.

(b) None of the funds appropriated or otherwise made available under this Act may be used to acquire an information technology system described in an assessment required by subsection (a) and produced, manufactured or assembled by one or more entities that are owned, directed or subsidized by the People's Republic of China unless the head of the assessing entity described in subsection (a) determines, and reports that determination to the Committees on Appropriations of the House of Representatives and the Senate, that the acquisition of such system is in the national interest of the United States.

This could turn out to be a harsh blow for companies like Lenovo that have so far escaped the spotlight trained on Huawei and ZTE. But it may also bring some surprises for American companies selling commercial IT gear to the government. It's not clear that they even know which of their suppliers and assemblers are directed or subsidized by the Chinese government. Where the IT system is manufactured doesn't answer the question; sanctions will depend not on where the system is made but on whether the company that supplies it is tainted by close ties to China's government.

It will make life equally awkward for the Obama Administration, which has been slowly and hesitantly toughening its stance on Chinese cyberespionage. The CR language will force the pace of retaliation, probably faster than the administration would like. But the statutory alternative to implementing the ban is for the administration to certify purchases as in the national interest -- possibly over the objections of FBI analysts who mistrust the gear.

The continuing resolution passed both houses with this provision in it; the President could in theory refuse to sign it. But this is a much-anticipated funding bill that heads off a government shutdown. With Congress having for once avoided a Perils-of-Pauline crisis, it's politically impossible for the President to put Pauline back on the railroad tracks -- especially so the government can buy suspect equipment from China. A veto is even less palatable than living with the provision.

Comments

We must be very vigilant with the Chinese electronics
I perfectly capable the Chinese government
have a plan of attack consisting manipulate
with countless hidden programs electronic devices
to disable them or get them to send information to the Chinese military
ESPECIALLY AVOID USE BY THE ARMY USA in any electronic gun.
Any plane carrying Chinese electronics with hidden malware or by radio signals can be monitored and tracked, you can turn off their engines, any computer in the Pentagon might send secret information to China.
Apart from its use in the industry of all kinds (military or civilian)
would help them to make industrial espionage
SORRY, GOOGLE TRADUCTOR (I LIVE ON SPAIN)